CVE-2024-8775 describes a flaw in Ansible where sensitive data from Ansible Vault files can be exposed in plaintext within playbook output or logs if the no_log: true parameter is not used when loading vaulted variables via tasks like include_vars. This medium-severity vulnerability (CVSS 5.5) has a low attack complexity and requires local access, potentially leading to the disclosure of secrets like passwords or API keys. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2.4 For RHEL 8 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Ansible Automation Platform 2.4 For RHEL 9 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Ansible Automation Platform 2.5 For RHEL 8 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Ansible Automation Platform 2.5 For RHEL 9 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Enterprise Linux AI (RHEL AI) | All Versions ImpactedCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Ansible vulnerable to Insertion of Sensitive Information into Log File
Sep 16, 2024ansible-core: Exposure of Sensitive Information in Ansible Vault Files Due to Improper Logging
Sep 13, 2024Ansible-core: exposure of sensitive information in ansible vault files due to improper logging
Sep 10, 2024